Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fj76-6r22-qfgv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to the nagios user account, because this directory is writable in between a call to emake and a call to fowners.

Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to the nagios user account, because this directory is writable in between a call to emake and a call to fowners.

EPSS

Процентиль: 26%
0.0009
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-281
CWE-362

Связанные уязвимости

CVSS3: 5.5
nvd
около 6 лет назад

Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to the nagios user account, because this directory is writable in between a call to emake and a call to fowners.

EPSS

Процентиль: 26%
0.0009
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-281
CWE-362